Skip to content

Hunting Hypothesis

Definition

A testable statement specifying what adversary behaviour might be present, which data source would show it, and what analytic would surface it. A hypothesis is the starting point for every structured hunt and must be specific enough to produce a falsifiable query.

Definition
Testable statement of possible adversary behaviour
Required components
Behaviour, data source, and analytic
Key property
Must be falsifiable and specific
Role
Starting point for a structured threat hunt

Common questions

How is a hunting hypothesis different from a SIEM alert rule?+

An alert rule fires automatically on a known signature or threshold, while a hunting hypothesis drives a human-led, exploratory investigation into behaviour that may not yet have a signature, often informed by threat intelligence or an intuition about a gap in existing detections.

Where do hunters typically source hypotheses from?+

Common sources include threat intelligence reporting on adversary tactics, MITRE ATT&CK technique coverage gaps, results of prior incidents, and anomalies noticed during routine monitoring that do not yet have an explanation.

What makes a hunting hypothesis too vague to be useful?+

A hypothesis like looking for suspicious activity gives no specific data source or analytic to apply, whereas a workable hypothesis names the behaviour, such as lateral movement via a specific protocol, the log source that would show it, and the query or analytic that would surface it.

Related terms

Dwell Time
The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
Tactics, Techniques, and Procedures (TTPs)
A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
Threat Hunting
A proactive, human-led process that searches for evidence of adversary activity in an environment under the assumption that automated controls have been...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.